Check Point reports exploitation of management-server flaw; F5 APM attacks also reported
Check Point issued emergency fixes for CVE-2026-93616, which the company says had been exploited since at least July 23, 2026. It also said attackers began probing a separate pre-authentication remote-code-execution flaw in Quantum Security Gateway shortly after patches were released on September 9. The report’s headline also references attacks on F5 BIG-IP APM, but its available content provides no details on those attacks.
What changed For the separate Quantum Security Gateway flaw, patches released on September 9 were followed by probing within days; the excerpt does not establish successful exploitation.
Why it matters Management Server operators face an incident-response question as well as a patching task: exploitation dating back to July 23 gives them reason to assess historical exposure.
HelpNet Security ↗